Manufacture, production and distribution of chemicals is in Annex 2 to OUG 155/2024. Medium-sized and large companies are important entities, with standard scores of 120 and 180, so the important level in both cases. What sets the sector apart is something else: here, a cyber incident can become a safety incident.

Who is covered by NIS2 in the chemical industry

Annex 2 to OUG 155/2024 takes over the list in the NIS2 Directive, which uses the definitions in Regulation (EC) No 1907/2006 (REACH). It covers:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law60basic34 controls, threshold 2.5
Mediumimportant120important133 controls, threshold 3
Largeimportant180important133 controls, threshold 3

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Find your level and maturity score in a few minutes. The calculator opens with the “Chemicals” sector already selected; you choose the size and answer 12 questions.

Calculate the level for chemicals

Which systems are assessed in a chemical plant

In a chemical plant, process and safety systems matter as much as the office network. The assessment usually covers:

Triton: when the target is the safety system

In 2017, at a petrochemical plant in Saudi Arabia, attackers reached the Triconex safety instrumented systems made by Schneider Electric, with purpose-built malware later named Triton or Trisis. A first plant shutdown, in June, was blamed on a mechanical fault. After the second, in August, investigators found the malware. The attackers had been in the company’s IT network for years.

Safety systems are the last barrier before an accident. In the NIS2 assessment they deserve separate treatment: in the inventory, in their own network segment, with remote access limited to what is strictly needed and with every change made only through a procedure.

For companies also covered by the Seveso legislation on major accidents involving dangerous substances, the emergency plan and the cyber incident response plan must fit together: the same team, the same scenarios, the same contacts.

What comes next

How TRU helps

In the chemical industry, testing must not touch the process. We start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a chemical distributor without a plant covered?

Yes, if it is medium-sized or large. Distribution of substances and mixtures is in the annex, not just manufacturing.

We make medicines. Are we covered under chemicals?

No. Manufacturing pharmaceutical products is in the health sector, in Annex 1, with a different score and entity type: a large company is an essential entity.

What level does a large chemical company have?

The important level: the standard score is 180, below the 200 threshold for the essential level. You apply 133 controls, with a threshold of 3 at self-assessment.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · MIT Technology Review, on Triton, 5 March 2019.